LunarLoader — Malware Profile
LunarLoader is the loader component for the LunarWeb and LunarMail backdoors that has been used by Turla since at least 2020 including against a European ministry of foreign affairs (MFA). LunarLoader has been observed as a standalone and as a part of trojanized open-source software such as AdmPwd.
MITRE ATT&CK techniques (5)
- T1016 System Network Configuration Discovery
- T1137.006 Add-ins
- T1140 Deobfuscate/Decode Files or Information
- T1480 Execution Guardrails
- T1620 Reflective Code Loading